Berliner Boersenzeitung - Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst

EUR -
AED 4.195799
AFN 72.545262
ALL 94.373378
AMD 420.516584
ANG 2.04552
AOA 1047.664661
ARS 1669.737728
AUD 1.638439
AWG 2.056485
AZN 1.915954
BAM 1.951192
BBD 2.306888
BDT 140.408382
BGN 1.931817
BHD 0.431912
BIF 3415.632271
BMD 1.142492
BND 1.481278
BOB 7.897348
BRL 5.893655
BSD 1.145341
BTN 108.143585
BWP 15.544485
BYN 3.204703
BYR 22392.836377
BZD 2.303589
CAD 1.618819
CDF 2587.74347
CHF 0.924013
CLF 0.026309
CLP 1035.451024
CNY 7.740154
CNH 7.746636
COP 3930.319806
CRC 519.587055
CUC 1.142492
CUP 30.276029
CVE 110.678859
CZK 24.200773
DJF 203.963878
DKK 7.474495
DOP 66.955446
DZD 152.554686
EGP 56.834273
ERN 17.137375
ETB 181.827173
FJD 2.562437
FKP 0.863375
GBP 0.862895
GEL 3.021908
GGP 0.863375
GHS 12.830461
GIP 0.863375
GMD 83.401519
GNF 10035.686741
GTQ 8.715416
GYD 239.095302
HKD 8.956735
HNL 30.470429
HRK 7.532562
HTG 149.621405
HUF 352.498091
IDR 20415.183327
ILS 3.394743
IMP 0.863375
INR 108.117981
IQD 1496.664064
IRR 1570926.021079
ISK 143.94249
JEP 0.863375
JMD 180.980659
JOD 0.809973
JPY 184.591272
KES 147.836101
KGS 99.910684
KHR 4584.258768
KMF 492.413889
KPW 1028.242887
KRW 1757.180697
KWD 0.352642
KYD 0.954488
KZT 558.256206
LAK 25191.940644
LBP 102310.127428
LKR 382.985073
LRD 208.165004
LSL 18.819309
LTL 3.37348
LVL 0.691082
LYD 7.343339
MAD 10.682125
MDL 20.141622
MGA 4832.739286
MKD 61.615135
MMK 2399.138755
MNT 4089.242301
MOP 9.248709
MRU 45.779688
MUR 54.622615
MVR 17.663374
MWK 1986.06828
MXN 19.859978
MYR 4.729575
MZN 73.000192
NAD 18.819227
NGN 1563.054356
NIO 41.849596
NOK 11.099621
NPR 173.396514
NZD 2.004319
OMR 0.439295
PAB 1.142901
PEN 4.207825
PGK 4.985548
PHP 70.18666
PKR 317.784078
PLN 4.27669
PYG 6982.421087
QAR 4.165551
RON 5.236383
RSD 117.347575
RUB 84.836309
RWF 1673.179024
SAR 4.288561
SBD 9.214242
SCR 15.148116
SDG 686.068212
SEK 11.007165
SGD 1.478321
SHP 0.852985
SLE 28.276973
SLL 23957.48288
SOS 654.557716
SRD 42.764032
STD 23647.270512
STN 24.67782
SVC 10.021778
SYP 126.281999
SZL 18.747925
THB 37.723361
TJS 10.600763
TMT 4.010146
TND 3.326363
TOP 2.750846
TRY 53.098673
TTD 7.767244
TWD 36.134608
TZS 3002.733115
UAH 51.513002
UGX 4172.146184
USD 1.142492
UYU 45.70206
UZS 13704.187802
VES 704.763427
VND 30072.66526
VUV 135.216519
WST 3.143904
XAF 655.814443
XAG 0.01805
XAU 0.000276
XCD 3.087641
XCG 2.064242
XDR 0.815619
XOF 655.808704
XPF 119.331742
YER 272.655331
ZAR 18.772074
ZMK 10283.794611
ZMW 20.301498
ZWL 367.881846
  • CMSC

    -0.2100

    22.16

    -0.95%

  • CMSD

    -0.2100

    22.08

    -0.95%

  • BCC

    -2.1200

    72.54

    -2.92%

  • RIO

    -0.7200

    99.36

    -0.72%

  • NGG

    1.5300

    80.97

    +1.89%

  • BTI

    -0.0100

    58.9

    -0.02%

  • BCE

    -0.6300

    22.65

    -2.78%

  • BP

    0.6800

    39.78

    +1.71%

  • RBGPF

    -0.2700

    60.34

    -0.45%

  • GSK

    0.0700

    50.74

    +0.14%

  • JRI

    -0.0200

    12.65

    -0.16%

  • RELX

    -0.3500

    30.83

    -1.14%

  • RYCEF

    0.2300

    18.63

    +1.23%

  • AZN

    1.5000

    176.43

    +0.85%

  • VOD

    -0.1800

    14.12

    -1.27%

Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst
Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst

Mandatory Chinese Olympics app has 'devastating' encryption flaw: analyst

An app all attendees of the upcoming Beijing Olympics must use has encryption flaws that could allow personal information to leak, a cyber security watchdog said Tuesday.

Text size:

The "simple but devastating flaw" in the encryption of the MY2022 app, which is used to monitor Covid and is mandatory for athletes, journalists and other attendees of the games in China's capital, could allow health information, voice messages and other data to leak, warned Jeffrey Knockel, author of the report for Citizen Lab.

The International Olympic Committee responded to the report by saying users can disable the app's access to parts of their phones and that assessments from two unnamed cyber security organizations "confirmed that there are no critical vulnerabilities."

"The user is in control over what the... app can access on their device," the committee told AFP, adding that installing it on cellphones isn't required "as accredited personnel can log on to the health monitoring system on the web page instead."

The committee said it had asked Citizen Lab for its report "to understand their concerns better."

Citizen Lab said it notified the Chinese organizing committee for the Games of the issues in early December and gave them 15 days to respond and 45 days to fix the problem, but received no reply.

"China has a history of undermining encryption technology to perform political censorship and surveillance," Knockel wrote.

"As such, it is reasonable to ask whether the encryption in this app was intentionally sabotaged for surveillance purposes or whether the defect was born of developer negligence," he continued, adding that "the case for the Chinese government sabotaging MY2022's encryption is problematic."

The flaws affect SSL certificates, which allow online entities to communicate securely.

MY2022 doesn't authenticate SSL certificates, meaning other parties could access the app's data, while data is transmitted without the usual encryption SSL certificates have, Knockel wrote.

While the app is transparent about the medical information it collects as part of China's efforts to screen Covid-19 cases, he said "it is unclear with whom or which organization(s) it shares this information."

MY2022 also contains a list called "illegalwords.txt" of "politically sensitive" phrases in China, many of which relate to China's political situation or its Tibetan and Uighur Muslim minorities.

These include keywords like "CCP evil" and Xi Jinping, China's president, though Knockel said it was unclear if the list was being actively used for censorship purposes.

Because of these features, the app may violate both Google and Apple policies around smartphone software, and "also China's own laws and national standards pertaining to privacy protection, providing potential avenues for future redress," he wrote.

(T.Burkhard--BBZ)